Privacy Policy
Last updated: April 27, 2026
This Privacy Policy describes how WarmupTool ("we", "us") handles information when you use our web application and related services (the "Service"). By using the Service, you agree to this policy.
What we collect
- Account data: email address and password hash you provide when you register.
- Mailbox configuration: SMTP/IMAP hostnames, ports, provider preset labels, and flags you set for warmup behavior (send mode, receive mode, limits, etc.).
- Credentials for mail access: app passwords or OAuth refresh tokens needed to send or receive mail on your behalf, depending on how you connect a mailbox.
- Warmup activity: records of outbound messages we create for your accounts (subjects, bodies, recipient addresses, status, and timestamps) so you can monitor the Service.
- Technical logs: standard server logs may include IP address, user agent, request path, and error diagnostics for security and reliability.
How we use information
We use the information above to:
- Authenticate you and operate your account.
- Connect to your mail providers to send warmup mail and optional replies.
- Store configuration and history so the dashboard and APIs work.
- Maintain security, prevent abuse, and debug operational issues.
Google OAuth
If you connect Gmail via Google, Google's OAuth consent screen applies. We request the scopes needed to access Gmail as configured in the app. We store a refresh token server-side so the Service can obtain short-lived access tokens when mail operations run. You can revoke access at any time from your Google Account security settings.
Third parties
We send mail through your providers (for example Gmail, Microsoft, or your SMTP host). Those providers process message content under their own policies. If you enable AI-assisted message drafting, the Service may call an external AI API you configure (for example xAI) to generate message text. Do not enable that unless you accept their terms.
Retention
We retain account and mailbox data until you delete it or delete your account. You can remove connected mailboxes from the app UI. Warmup message records may be removed when you delete the originating mailbox or account, depending on database rules.
Security
We use industry-standard practices appropriate for an early-stage product, including encrypted transport (HTTPS), hashed passwords, and restricted database access. No online service can guarantee perfect security.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data. Contact us using the email below and we will respond within a reasonable time.
Children
The Service is not intended for children under 16. We do not knowingly collect personal information from children.
Changes
We may update this policy from time to time. We will post the new date at the top of this page. Continued use after changes means you accept the updated policy.
Contact
Questions about privacy: replace this placeholder with your support email in production: privacy@yourdomain.com